2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31585 | MEDIUM | 6.7 | 0.9% | Jun 23, 2021 | Accellion Kiteworks before 7.3.1 allows a user with Admin privileges to escalate their privileges by generating SSH pass... |
| CVE-2021-21999 | HIGH | 7.8 | 1.4% | Jun 23, 2021 | VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App... |
| CVE-2021-21998 | CRITICAL | 9.8 | 10.6% | Jun 23, 2021 | VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A mal... |
| CVE-2021-35210 | MEDIUM | 6.1 | 0.7% | Jun 23, 2021 | Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject ... |
| CVE-2021-29087 | HIGH | 7.5 | 1.4% | Jun 23, 2021 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno... |
| CVE-2021-29086 | HIGH | 7.5 | 1.2% | Jun 23, 2021 | Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Man... |
| CVE-2021-29085 | HIGH | 7.5 | 1.3% | Jun 23, 2021 | Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file... |
| CVE-2021-29084 | HIGH | 7.5 | 1.3% | Jun 23, 2021 | Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Secu... |
| CVE-2021-27649 | CRITICAL | 9.8 | 2.0% | Jun 23, 2021 | Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-2542... |
| CVE-2021-34397 | LOW | 2.3 | 0.2% | Jun 22, 2021 | Bootloader contains a vulnerability in NVIDIA MB2, which may cause free-the-wrong-heap, which may lead to limited denial... |
| CVE-2021-34396 | LOW | 2.3 | 0.2% | Jun 22, 2021 | Bootloader contains a vulnerability in access permission settings where unauthorized software may be able to overwrite N... |
| CVE-2021-34395 | MEDIUM | 4.2 | 0.2% | Jun 22, 2021 | Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a re... |
| CVE-2021-34394 | MEDIUM | 6.7 | 0.3% | Jun 22, 2021 | Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deser... |
| CVE-2021-34393 | MEDIUM | 4.4 | 0.3% | Jun 22, 2021 | Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not exp... |
| CVE-2021-34392 | MEDIUM | 5.5 | 0.2% | Jun 22, 2021 | Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the tz_map_shared_mem function... |
| CVE-2021-34391 | MEDIUM | 5.5 | 0.2% | Jun 22, 2021 | Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an i... |
| CVE-2021-34390 | MEDIUM | 5.5 | 0.2% | Jun 22, 2021 | Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an i... |
| CVE-2021-34372 | HIGH | 7.8 | 0.3% | Jun 22, 2021 | Trusty (the trusted OS produced by NVIDIA for Jetson devices) driver contains a vulnerability in the NVIDIA OTE protocol... |
| CVE-2021-32701 | HIGH | 7.5 | 1.3% | Jun 22, 2021 | ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o... |
| CVE-2021-32700 | HIGH | 7.4 | 0.6% | Jun 22, 2021 | Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.... |
| CVE-2021-32699 | MEDIUM | 6.5 | 0.3% | Jun 22, 2021 | Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl ... |
| CVE-2021-22383 | MEDIUM | 4.9 | 0.6% | Jun 22, 2021 | There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SP... |
| CVE-2021-22382 | MEDIUM | 6.5 | 0.2% | Jun 22, 2021 | Huawei LTE USB Dongle products have an improper permission assignment vulnerability. An attacker can locally access and ... |
| CVE-2021-22378 | MEDIUM | 5.3 | 0.4% | Jun 22, 2021 | There is a race condition vulnerability in eCNS280_TD V100R005C00 and V100R005C10. There is a timing window exists in wh... |
| CVE-2021-22377 | HIGH | 7.2 | 0.9% | Jun 22, 2021 | There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now